You can't secure what you don't acknowledge.SM

Wednesday, February 6, 2008

Be careful co-mingling passwords

With all things being electronic today and us having to manage a hundred different computer accounts between home and work, here's one of those 'haven't thought of before' security issues that can come back and bite hard when the opportunity arises.

First, have one set of common passwords you use for business purposes...You know - the account password(s) you use on the network, email, local computer, PGP, your HR portal - you name it. Sure, in an ideal world, we'd have separate passwords for every single account. That's not reality. All of us have re-used the same password on different systems....at least at some point.

Second, have another set of common passwords you use at home for things like Amazon.com, eBay, your personal email account, online banking, etc. When you're at home, at friend's houses, or just goofing off on vacation, you're likely to be using less secure systems and communications channels which increases the chances of password exposure.

Sure, it may be convenient to co-mingle work and personal passwords, but in the end it will only serve to increase the odds for an incident and exposure where you don't need it - either professionally or personally.

Most importantly - make it policy (I know...it'd be next to impossible to enforce - but still) and then get the word out to your users. They're you're biggest vulnerability in all of this after all.

No comments:

Post a Comment